Anthropic reported persistent distillation attacks by Chinese AI companies including Alibaba, Moonshot AI, and DeepSeek, with nearly 200 million malicious exchanges observed over recent months. The attackers used sophisticated techniques to extract Claude's internal reasoning chains and chain-of-thought capabilities to train their own models. Alibaba's campaign was the largest, involving 151 million exchanges across 3,500 accounts between May and July 2026.